Security News

Linux Backdoors Hide as Email Traffic on Telecom and Network Appliances

Infosecurity Magazine · 6 Oct 2026
Key Takeaway Do not assume traffic is safe because it looks like normal email: monitor what your gateways, NAS units and other edge devices connect to, and retire unsupported appliances.

Rapid7 published research on October 2 describing Linux backdoors used against telecom and network-edge appliances in South Korea and Taiwan. The malware includes a new BPFDoor variant, a BPF Rekoobe build, and a dropper plus six builds of an implant Rapid7 calls AVERAT. Each is designed to blend in, by disguising its traffic as email and naming its processes after legitimate services on the compromised device.

AVERAT connects out on TCP port 25 and uses the standard email protocol, then requests encryption before starting its own encrypted session. On a mail security gateway, where outbound mail is the device's normal job, Rapid7 said this looks the same as legitimate activity in flow records. The implant checks in roughly every 10 to 12 minutes and supports file transfers, ending processes, up to ten concurrent shell sessions and proxy or port-forwarding channels. The Rekoobe sample and one BPFDoor variant impersonate components of a South Korean anti-spam product, and Rapid7 said firewall rules allowing mail relay could let a trigger packet reach the implant. Another BPFDoor controller wraps its trigger in HTTPS requests, which may help it pass edge proxies and evade deep-packet inspection.

Three AVERAT builds report to addresses on compromised third-party devices in Taiwan: a Synology NAS, an obsolete small-business appliance and a Dahua video recorder. Rapid7 believes the operators installed an identical VPN service on each. The relays match a CISA advisory profile for China-nexus covert networks, but Rapid7 found no overlap with any named network and said attribution is ongoing.

Linux malware BPFDoor Network edge security Telecommunications

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.